manage.get.gov/docs/compliance/dist/system-security-plans/ato/ir-6.md
Logan McDonald 1d3dfdb8d5
Add compliance documentation to source control (#116)
* add initial setup of compliance-trestle
2022-09-14 08:46:43 -04:00

1.6 KiB

implementation-status control-origination
c-not-implemented
c-inherited-cloud-gov
c-inherited-cisa
c-common-control
c-system-specific-control

ir-6 - [catalog] Incident Reporting

Control Statement

  • [a] Require personnel to report suspected incidents to the organizational incident response capability within time period ; and

  • [b] Report incident information to authorities.

Control guidance

The types of incidents reported, the content and timeliness of the reports, and the designated reporting authorities reflect applicable laws, executive orders, directives, regulations, policies, standards, and guidelines. Incident information can inform risk assessments, control effectiveness assessments, security requirements for acquisitions, and selection criteria for technology products.

Control assessment-objective

personnel is/are required to report suspected incidents to the organizational incident response capability within time period; incident information is reported to authorities.


What is the solution and how is it implemented?


Implementation a.

Add control implementation description here for item ir-6_smt.a


Implementation b.

Add control implementation description here for item ir-6_smt.b